An effective FCA compliance function should do two things well: help the business understand its regulatory obligations and independently test whether the controls designed to meet them actually work. The exact legal requirements differ by firm type, so a firm should not copy the organisational model of a MiFID investment firm and assume it is mandatory across every FCA sector.
SYSC 6.1 contains the central FCA framework. It requires adequate policies and procedures for regulatory compliance and, for specified firms, a permanent and effective compliance function with detailed requirements on monitoring, independence, authority, resources, expertise and access to information. Other firms are directed to take parts of that framework into account as guidance depending on the applicable SYSC provisions.
The practical standard is therefore proportionate but not vague. Senior management should be able to explain who owns compliance risk, what the compliance function monitors, how its priorities are set, whether it has enough authority and information to challenge the business, and how significant deficiencies reach the governing body.
Start with the SYSC application rules for the specific firm
SYSC 6.1 does not apply identically to every authorised firm. Common platform firms, management companies, operators of electronic systems in relation to lending and other categories have different combinations of rules and guidance, while SYSC 1 Annex 1 affects how provisions apply to other firms.
A compliance framework should therefore begin with a legal-entity applicability map. That map should identify which requirements are binding rules for the firm, which provisions apply as guidance and whether additional sector rules impose specific oversight responsibilities.
This matters for organisational design. A statement that the FCA always requires a separate independent compliance department is too broad. For some firms the Handbook contains a permanent and effective compliance-function requirement, while for other firms the need for a separate function depends on the nature, scale and complexity of the business.
Adequate policies and procedures are the base requirement
SYSC 6.1.1 requires a firm to establish, implement and maintain adequate policies and procedures sufficient to ensure compliance by the firm, its managers, employees and appointed representatives where relevant with obligations under the regulatory system, and to counter the risk that the firm may be used to further financial crime.
The key words are establish, implement and maintain. A policy that exists but is not embedded in systems, training and business processes provides limited evidence of compliance. The framework should be capable of identifying which controls implement each material obligation and who owns them.
Policies should also remain consistent with the live business. Product expansion, new ARs, outsourcing, acquisition or technology change can make an apparently current manual materially inaccurate if the operating model has moved on.
Risk-based monitoring should start from a compliance risk assessment
For common platform firms, SYSC 6.1.3-B requires the compliance function to conduct an assessment and establish a risk-based monitoring programme covering the firm's designated investment business and relevant ancillary activity. The programme must set priorities determined by the compliance risk assessment so compliance risk is comprehensively monitored.
Even where that exact rule does not bind another firm, the concept is strong compliance practice: monitoring should respond to actual regulatory risk rather than repeat the same calendar because it was used last year.
The risk assessment should consider business volume, customer type, product complexity, complaints, regulatory change, previous findings, ARs, outsourcing and other evidence relevant to the firm. High-risk areas should receive deeper or more frequent testing, while lower-risk controls can be reviewed proportionately.
Compliance monitoring is different from first-line control ownership
The business remains responsible for operating the controls required in its activities. Compliance should not become the first-line operator of every regulatory process and then claim independence by checking its own work.
A sales team, product owner, operations function or other business area should normally own the process it performs. Compliance can advise on the regulatory requirement, challenge design and monitor operating effectiveness. The exact three-lines model is not prescribed for every FCA firm, but the distinction between control ownership and independent oversight is important.
Where a small firm cannot achieve complete organisational separation, it should identify the conflict and design proportionate safeguards. That may include independent review by another senior person or external assurance for a higher-risk area rather than pretending the self-review issue does not exist.
Independence requires authority, information and freedom from conflicted incentives
For common platform firms, SYSC 6.1.3-C requires the compliance function to have the necessary authority, resources, expertise and access to relevant information. It also addresses management-body appointment of the compliance officer, direct ad-hoc reporting on significant compliance risk, involvement in monitored activities and remuneration that could compromise objectivity.
These conditions show that independence is operational rather than cosmetic. A compliance officer with an impressive title but no access to complaints, customer files, product decisions or senior committees cannot provide effective challenge.
Remuneration and reporting lines should also support objectivity. The firm should understand whether commercial targets could discourage challenge and whether compliance can escalate a serious issue directly to the governing body when necessary.
Resources should be assessed against the business, not headcount alone
Adequate resources include people, expertise, systems, data access and time. A small compliance team can be sufficient for a simple business, while a larger team can still be under-resourced if the firm has complex products, rapid growth, many ARs or significant regulatory change.
The assessment should consider workload and capability. If monitoring is repeatedly deferred because advisory work consumes all available capacity, the issue is not solved by describing the programme as risk based. Senior management should understand which assurance work is not being completed and the regulatory consequence.
Specialist expertise can be sourced externally where appropriate, but the firm should retain enough internal knowledge to understand the advice, make decisions and oversee the provider. External support is not a transfer of the firm's regulatory accountability.
The compliance officer needs a clear mandate and governing-body access
Where the applicable SYSC rule requires a compliance officer, the role should be clearly defined and supported by the management body. The officer should understand which reports, committees and escalation routes form part of the mandate.
For common platform firms, SYSC 6.1.3-A includes at least annual reporting to the management body on the implementation and effectiveness of the overall control environment for designated investment business, identified risks, complaints-handling reporting and remedies. Significant compliance risk also has a direct ad-hoc reporting route under SYSC 6.1.3-C.
Other firms should use the reporting model appropriate to their applicable requirements and size. The central principle is that material compliance risk reaches people with authority to act before it becomes a recurring customer or regulatory problem.
Complaints and customer outcomes should feed compliance monitoring
For common platform firms, the current SYSC 6.1 framework explicitly connects complaints handling with compliance monitoring. More broadly, complaints, Consumer Duty outcomes and regulatory data are valuable evidence of whether controls operate effectively.
A compliance programme should therefore not sit separately from customer evidence. Repeated complaints about one fee, adviser, AR or support journey can indicate a control weakness that requires targeted review even where the annual monitoring plan originally focused elsewhere.
The same applies to regulatory returns and operational incidents. Compliance should be able to change priorities when live evidence shows risk increasing rather than wait for the next annual planning cycle.
Outsourced compliance support needs retained ownership and challenge
Firms can use external compliance consultants for advice, monitoring, policy work or specialist review. The governance should make clear what the provider does, what information it receives, who signs off conclusions and who remains responsible for regulatory decisions.
A consultant should not become a substitute management body. The firm needs internal owners who understand material findings and can direct remediation, while outsourced monitoring should have enough independence from the activities it is testing.
Service scope should be reviewed as the business changes. A retainer designed for a small authorised firm can become inadequate after growth, acquisition or new permissions even where the contractual hours have not changed.
Findings should lead to root-cause remediation and retesting
A compliance function is ineffective if it identifies the same issue repeatedly without changing the underlying process. Findings should identify regulatory significance, customer impact, root cause, owner, deadline and closure evidence.
Training can be useful where the cause is knowledge, but it will not fix a system that allows the wrong fee to be charged or an incentive that rewards poor conduct. Compliance should challenge whether the proposed action addresses the cause rather than simply closes the item administratively.
Material remediation should be retested. Completion of a policy update or system release shows that an action occurred, not that the control now produces the intended outcome.
What should senior management expect from the compliance function in 2026?
Senior management should receive a current compliance risk assessment, a monitoring programme linked to those risks, clear reporting on material findings and overdue remediation, regulatory change analysis and escalation of significant emerging issues.
The governing body should also understand limitations. Where data is poor, compliance lacks specialist expertise or a monitoring area has been deferred, that uncertainty should be visible rather than converted into a green status.
The test is whether the function can influence decisions before harm occurs and independently identify when the business's own controls are not working. That is a stronger measure of effectiveness than the number of policies reviewed or monitoring tests completed.
How Regulatory Counsel can support
Regulatory Counsel supports FCA-regulated firms with the regulatory, governance and remediation issues covered in this article. We can review the existing framework, identify gaps and support practical implementation or independent assurance.
Speak to Regulatory Counsel to discuss this area.
Frequently Asked Questions
No. The detailed SYSC requirements vary by firm type, and for some firms the need for a separate compliance function is proportionate to the nature, scale and complexity of the business.
It requires adequate policies and procedures sufficient to ensure compliance with the regulatory system and to counter the risk that the firm may be used to further financial crime.
Yes. SYSC 6.1.3-B requires the compliance function to establish a monitoring programme whose priorities are determined by the compliance risk assessment.
External support can be used, but the regulated firm retains responsibility for its obligations and needs adequate internal ownership and oversight.
Yes. We can assess applicability, compliance risk assessment, monitoring, independence, resources, governance, reporting, outsourced support and remediation.